Vulnerability Details CVE-2018-1193
Cloud Foundry routing-release, versions prior to 0.175.0, lacks sanitization for user-provided X-Forwarded-Proto headers. A remote user can set the X-Forwarded-Proto header in a request to potentially bypass an application requirement to only respond over secure connections.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 39.0%
CVSS Severity
CVSS v3 Score 5.3
CVSS v2 Score 5.0
Products affected by CVE-2018-1193
-
cpe:2.3:a:cloudfoundry:cf-deployment:-
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.0.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.0.1
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.0.2
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.1.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.10.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.11.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.12.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.13.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.14.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.15.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.16.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.17.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.18.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.19.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.2.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.2.1
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.2.2
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.20.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.21.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.22.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.23.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.24.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.25.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.26.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.27.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.28.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.29.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.3.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.30.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.31.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.32.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.32.1
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.33.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.34.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.35.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.36.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.37.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.4.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.5.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.7.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.8.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.9.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.9.1
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.0.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.1.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.10.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.11.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.12.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.13.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.14.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.15.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.16.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.17.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.18.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.19.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.2.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.20.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.21.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.22.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.23.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.24.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.25.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.26.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.3.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.3.1
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.4.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.5.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.6.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.7.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.8.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.9.0
-
cpe:2.3:a:cloudfoundry:routing-release:-
-
cpe:2.3:a:cloudfoundry:routing-release:0.118.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.121.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.122.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.123.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.126.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.133.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.134.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.135.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.136.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.137.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.138.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.139.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.140.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.141.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.142.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.143.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.144.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.144.1
-
cpe:2.3:a:cloudfoundry:routing-release:0.145.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.146.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.147.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.149.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.150.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.151.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.152.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.153.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.154.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.155.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.156.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.157.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.158.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.159.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.160.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.161.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.162.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.163.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.164.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.165.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.166.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.167.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.168.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.169.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.170.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.171.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.172.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.173.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.174.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.62.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.66.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.69.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.99.0